CVE-2019-19794
Summary
| CVE | CVE-2019-19794 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-13 22:15:00 UTC |
| Updated | 2020-01-02 17:36:00 UTC |
| Description | The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Use crypto/rand for random id generation. by jsha · Pull Request #1044 · miekg/dns · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CoreDNS 1.6.6 Release Tracking · Issue #3519 · coredns/coredns · GitHub |
MISC |
github.com |
Issue Tracking, Third Party Advisory |
| [security] Predictable TXID can lead to response forgeries · Issue #1043 · miekg/dns · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Third Party Advisory |
| [Security] CVE-2019-19794 · Issue #3547 · coredns/coredns · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| Comparing v1.1.24...v1.1.25 · miekg/dns · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982542 Go (go) Security Update for github.com/miekg/dns (GHSA-44r7-7p62-q3fr)